Defense Federal Acquisition Regulation Supplement
The DFARS is a set of rules the Department of Defense (DoD) uses to guide how it buys goods and services. It adds defense-specific requirements on top of the government-wide Federal Acquisition Regulation (FAR). In practice, it tells DoD components and their contractors what additional policies and procedures apply to defense contracts.
The Defense Federal Acquisition Regulation Supplement (DFARS) is maintained by the Defense Acquisition Regulations System within DoD and provides uniform acquisition policies and procedures that supplement the FAR for the Department of Defense. It contains requirements of law, DoD-wide policies, delegations of FAR authorities, deviations from FAR requirements, and related implementing guidance; as used in the DFARS, 'departments and agencies' refers to the military departments and the defense agencies. The DFARS is accompanied by companion Procedures, Guidance, and Information (PGI) that supports internal DoD acquisition procedures. Practitioners should distinguish the DFARS as an acquisition regulation from specific cybersecurity-related clauses implemented through it, and should verify the current text of any subpart or clause against the official DFARS, as content changes across revisions and rulemakings.
Why it matters
The DFARS is the primary vehicle through which the Department of Defense translates statutory requirements, DoD-wide policies, and defense-specific priorities into binding acquisition terms. Because it supplements the government-wide Federal Acquisition Regulation (FAR) rather than replacing it, any organization doing business with DoD components is generally subject to both the FAR and the applicable DFARS provisions. Misunderstanding this layered relationship is a common and costly error: a contractor familiar with civilian agency contracting under the FAR cannot assume those terms fully describe its obligations on a defense contract, because the DFARS may add, delegate, or deviate from FAR requirements.
For compliance officers and contracting professionals, the DFARS matters because it is the mechanism that implements many defense-specific obligations, including cybersecurity-related clauses. An expert would caution against conflating the DFARS as an acquisition regulation with the individual clauses implemented through it; the regulation is the framework, while specific subparts and clauses carry the detailed requirements. Treating the DFARS as static is another frequent mistake, as its content changes across revisions and rulemakings published through the Federal Register, and relying on an outdated subpart can lead to noncompliance.
Because the DFARS carries requirements of law and DoD-wide policy, its provisions can have direct contractual and legal consequences. Practitioners should verify the current text of any subpart or clause against the official DFARS and its companion Procedures, Guidance, and Information (PGI) rather than relying on summaries, and should confirm which provisions apply to a given contract, as this entry does not cover the contractual or legal specifics of any individual clause.
Who it's relevant to
Inside DFARS
Common questions
Answers to the questions practitioners most commonly ask about DFARS.